CVE-2025-50063

Vulnerability in Oracle Java SE (component: Install).   The supported version that is affected is Oracle Java SE: 8u451. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. Note: Applies to installation process on client deployment of Java. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.3 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
oracleCNA
7.3 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
VendorProductVersion
oraclejdk
1.8.0
oraclejre
1.8.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openjdk-8
plucky
not-affected
noble
not-affected
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
openjdk-9
plucky
dne
noble
dne
jammy
dne
xenial
ignored
openjdk-lts
plucky
not-affected
noble
not-affected
jammy
not-affected
focal
not-affected
bionic
not-affected
openjdk-13
plucky
dne
noble
dne
jammy
dne
focal
ignored
openjdk-16
plucky
dne
noble
dne
jammy
dne
focal
ignored
openjdk-17
plucky
not-affected
noble
not-affected
jammy
not-affected
focal
not-affected
bionic
not-affected
openjdk-17-crac
plucky
not-affected
noble
dne
jammy
dne
openjdk-18
plucky
dne
noble
dne
jammy
ignored
openjdk-19
plucky
dne
noble
dne
jammy
ignored
openjdk-21
plucky
not-affected
noble
not-affected
jammy
not-affected
focal
not-affected
openjdk-21-crac
plucky
not-affected
noble
dne
jammy
dne
openjdk-24
plucky
not-affected
noble
dne
jammy
dne
openjdk-25
plucky
not-affected
noble
dne
jammy
dne